The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC PCS 7 V8.2
- SIMATIC PCS 7 V9.0
- SIMATIC PCS 7 V9.1
- SIMATIC WinCC V15 and earlier
- SIMATIC WinCC V16
- SIMATIC WinCC V17
- SIMATIC WinCC V7.4
- SIMATIC WinCC V7.5
- Summary
- Legitimate file operations on the web server of the affected systems do not properly neutralize special elements within the pathname. An attacker could then cause the pathname to resolve to a location outside of the restricted directory on the server and read, write or delete unexpected critical files.
- Remediation
- Update to V8.2 SP1; then update SIMATIC WinCC to V7.4 SP1 Update 19 or later version to fix CVE-2021-40358 and CVE-2021-40364
